Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora Core 3: 2005-188 Critical HelixPlayer Buffer Overflow

fedora
Calendar Grey March 3, 2005
Dist Fedora Esm H88
Important patch for HelixPlayer on Fedora Core 3 addresses two critical buffer overflow vulnerabilities, ensuring improved protection.
Updated HelixPlayer packages that fixes two buffer overflow issues are now available.

Summary

The Helix Player 1.0 is an open-source media player built in the Helix

Community for consumers. Built using GTK, it plays open source formats,

like Ogg Vorbis and Theora using the powerful Helix DNA Client Media

Engine.

Updated HelixPlayer packages that fixes two buffer overflow issues are

now

available.

This update has been rated as having critical security impact by the Red

Hat Security Response Team.

A stack based buffer overflow bug was found in HelixPlayer's

Synchronized Multimedia Integration Language (SMIL) file processor. An

attacker could create a specially crafted SMIL file which would execute

arbitrary code when opened by a user. The Common Vulnerabilities and

Exposures project (cve.mitre.org) has assigned the name CAN-2005-0455 to

this issue.

A buffer overflow bug was found in the way HelixPlayer decodes WAV

files. An attacker could create a specially crafted WAV file which could

execute arbitrary code when opened by a user. The Common Vulnerabilities

and Exposures project (cve.mitre.org) has assigned the name

CAN-2005-0611 to this issue.

All users of HelixPlayer are advised to upgrade to this updated package,

which contains HelixPlayer 1.0.3 which is not vulnerable to these

issues.

- Actually update to 1.0.3

* Thu Mar 3 2005 Ray Strode 1:1.0.3-2.fc3

- Update to 1.0.3 to fix 150098 and 150103.

- Add some execshield foo to stop some execstack regressions

- Add libogg-devel build req to tame compiler

6b65dacea8b1502caa8c98d0076f1d6e SRPMS/HelixPlayer-1.0.3-3.fc3.src.rpm

c385ef4c8ef6ee53ac7c784bb8fd7b58

x86_64/HelixPlayer-1.0.3-3.fc3.i386.rpm

c385ef4c8ef6ee53ac7c784bb8fd7b58 i386/HelixPlayer-1.0.3-3.fc3.i386.rpm

f8d4f9ae8b90ba0e506b83b1e8c0636f

i386/debug/HelixPlayer-debuginfo-1.0.3-3.fc3.i 386.rpm

This update can also be installed with the Update Agent; you can

launch the Update Agent with the 'up2date' command.

fedora-announce-list@redhat.com

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: HelixPlayer
Version: 1.0.3
Release: 3.fc3
Summary: Open source media player based on the Helix framework

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here